Multiple Reviewdog GitHub Actions were compromised with malicious code that dumped exposed secrets to workflow logs during a specific timeframe (March 11, 2025). This is a supply chain attack against CI/CD pipeline tools, not a direct internet-facing application vulnerability.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: OTHER
CVE Published: 2025-03-19
Added to CISA KEV: 2025-03-24 5 DAYS BETWEEN CVE AND KEV
CVE-2025-30154 is a critical supply chain vulnerability involving the compromise of the `reviewdog/action-setup@v1` GitHub Action?id=CVE-2025-30154?kagi_q=CVE-2025-30154.
CVE-2025-30154 - Major Reviewdog GitHub Action Supply Chain Compromise โ Full Timeline, Exploit Analysis, and Mitigation --- On March 11, 2025, a critical security incident struck the open source developer world: the popular reviewdog/action-setup GitHub Action was compromised, putting secrets and wโฆ
A GitHub action that installs reviewdog was compromised with malicious code that dumps secrets to Github Actions Workflow Logs. The vulnerability affects multiple reviewdog actions and has a CVSS score of 8.6 (HIGH).
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2025-30154โฆ
A GitHub Action was compromised on March 11, 2025, and exposed secrets to Github Actions Workflow Logs. The vulnerability affects multiple Reviewdog actions that use reviewdog/action-setup@v1 and has a CVSS score of 8.6.